CHRYSENE is a cyber espionage group targeting ICS environments in the energy sector.
Analyst brief
CHRYSENE (also known as OilRig, Greenbug) is a cyber espionage group targeting organizations in the oil, gas, and electricity production sectors, primarily in the Gulf region, Iraq, the United Kingdom, Pakistan, and Israel. This actor focuses on compromising ICS environments and is known to hand off compromised machines to other threat actors for further exploitation. Defenders should prioritize monitoring for phishing campaigns, vulnerability exploitation targeting industrial control systems, lateral movement towards OT assets, and anomalous connections to external C2 infrastructure.
CHRYSENE
OilRigGreenbug
unknown
Adversaries abusing ICS (based on Dragos Inc adversary list).
This threat actor targets organizations involved in oil, gas, and electricity production, primarily in the Gulf region, for espionage purposes. According to one cybersecurity company, the threat actor “compromises a target machine and passes it off to another threat actor for further exploitation.”